Account Management permissions
Users need specific permissions to access Account Management. Capabilities are guarded in Account Management by the permissions shown in the following table.
Permissions and capabilities
Each of the three account-level permissions:
- Access account
- Edit billing & account info
- Manage users
has a different set of capabilities in Account Management:
|Capability||Access account||Edit billing & account info||Manage users|
|License and subscription management|
|View Dynatrace Platform Subscription consumption and usage|
|Split HU quota (SaaS only)|
|Edit environment settings (SaaS only)|
|Lens – license summary|
|Lens account adoption|
|Lens environment information|
|IAM (SaaS only)|
|IAM oAuth clients|
Permissions are cumulative and are granted to the user using the appropriate Identity and Access Management interface, depending on whether you have a SaaS or Managed deployment.
SaaS deployments manage permissions in Account Management on the Identity & access management > People and Groups pages. In a SaaS deployment, a user must be assigned to a group with the appropriate permissions to access Account Management capabilities. Assign a user the Access account permission (see the permissions table above) when editing or creating the user. A user with none of these permissions can only manage their profile in Account Management.
Managed deployments manage permissions through the Cluster Management Console, which allows you to configure the account-level permissions needed to grant access to license and Lens capabilities.
Access environment = Access account in the permissions table above.
- A user only needs to be assigned to a group from within one cluster with the relevant account management permission.
- Cluster administrator is not a valid permission for Account Management. Additionally, the user that creates the first managed cluster can't be added to any other group and can't access Account Management.
A user can be associated with one or more accounts. Account Management redirects to the correct location based on the following URLs:
Opens the home page of the user's account. If the user is a member of multiple accounts, they're directed to the My accounts page (
https://myaccount.dynatrace.com/accounts) to select one.
Opens the My accounts page, which allows the user to select which account to open from the list of accounts to which the user has access.
Opens the home page of a specific account by
<account_uuid>. Bookmark these URLs to access your accounts directly.
Frequently asked questions
The permissions listed in the permissions table above are account-level permissions and are visible to Account Management. The cluster administrator permission is visible only at the cluster level and does not provide the visibility that Account Management requires to provide access.
If the user is added to a group with Access account or Edit billing & account info permissions, it may take a few minutes for the cluster to synchronize with the Dynatrace identity management system. If this does not resolve within 1 hour, you should contact Dynatrace ONE to let them know that user permissions are not synchronizing between your cluster and IDM.
Account Management is an account-level tool to help organizations manage their subscription across environments and clusters. You can govern access using the permissions in the permissions table above, but visibility is granted across clusters and environments.